SOC Analyst L4
Göteborg, SE, 417 15
Transport is at the core of modern society. Imagine using your expertise to shape sustainable transport and infrastructure solutions for the future. If you seek to make a difference on a global scale, working with next-gen technologies and the sharpest collaborative teams, then we could be a perfect match.
Transport is at the core of modern society. Imagine using your expertise to shape sustainable transport and infrastructure solutions for the future? If you seek to make a difference on a global scale, working with next-gen technologies and the sharpest collaborative teams, then we could be a perfect match.
Role Overview:
We are seeking a Principal Cyber Security Analyst to provide technical leadership within our Security Operations Center (SOC). In this role, you will serve as a hands-on expert in detecting, analyzing, and responding to cybersecurity threats. You will lead and coordinate major incident response efforts, set best practices for threat detection and investigation, and mentor senior and junior analysts across the SOC.
As a trusted security leader, you will collaborate closely with engineering, IT, risk, and business stakeholders to drive continuous improvements to the organization’s security posture, influence security strategy, and enhance detection and response capabilities
Key Responsibilities:
- Provide technical leadership for advanced threat detection, investigation and response within the SOC.
- Lead high-severity security incidents investigations, including malware analysis and enterprise-wide investigations.
- Drive real-time incident response, coordinating containment, remediation, and post-incident reviews.
- Design, optimize, and maintain detection use cases, monitoring rules, and alert tuning to improve SOC effectiveness.
- Perform deep analysis across networks, endpoints, and cloud environments to identify and mitigate security risks.
- Lead and support proactive threat-hunting initiatives and vulnerability mitigation efforts.
- Collaborate with IT, engineering, digital forensics, and external partners during incident response activities.
- Develop, standardize, and continuously improve SOC playbooks, procedures, and automation workflows.
- Mentor analysts, conduct training and incident response exercises, and perform quality reviews of investigations.
- Act as a subject matter expert, contributing to broader cybersecurity initiatives and continuous improvement programs.
Qualifications:
- 10+ years of progressive, hands-on experience in Security Operations, with deep expertise in SIEM and SOAR platforms within enterprise or large-scale SOC environments.
- Proven technical leadership in incident response, advanced threat detection, and security operations, including ownership of complex and high-impact security incidents.
- Expert-level experience with SIEM and SOAR technologies (e.g., Splunk, XSOAR), including detection engineering, use case development, and response automation.
- Strong scripting and automation capabilities using languages such as Python and PowerShell to enhance SOC efficiency and response maturity.
- In-depth knowledge of network and security protocols, firewalls, server and cloud environments, identity platforms (Active Directory, LDAP, Microsoft Entra ID), and modern attack techniques.
- Demonstrated experience in continuous security monitoring, vulnerability management, threat hunting, and adversary-based testing activities.
- Experience with Purple Team operations, detection validation, and/or OT security environments is highly desirable.
Certifications (Preferred):
CISSP, OffSec Defense Analyst (OSDA) GIAC Certified Incident Handler (GCIH), Certified SOC Analyst (CSA) or equivalent certifications.
Soft Skills:
- Strong communication, presentation, and collaboration skills.
- Analytical and critical thinking abilities.
- Sense of urgency and effective prioritization in high-pressure situations.
- Positive mindset and conflict resolution expertise.
ITIL Skills (Preferred):
Incident Management, Problem Management, and Audit/Assessment Experience.
Why Join Us?
- Opportunity to work on cutting-edge cybersecurity initiatives.
- Be part of a collaborative and forward-thinking team.
- Continuous learning and career development opportunities in the cybersecurity domain.
- Incident Management, Problem Management, and Audit/Assessment Experience.
We value your data privacy and therefore do not accept applications via mail.
“In some countries and for specific positions within Volvo Group Digital & IT, background checks may be required, in accordance with local laws & regulations. If this is applicable to the role you have applied for, you will be informed.”
Union representatives for Swedish applicants:
Akademikerna – Mikael Johansson, +46 73 902 34 30
Unionen – Lajla Dahlsjö, +46 31 322 45 75
Ledarna – Carina Sachade, +46 73 902 40 83
We value your data privacy and therefore do not accept applications via mail.
Who we are and what we believe in
We are committed to shaping the future landscape of efficient, safe, and sustainable transport solutions. Fulfilling our mission creates countless career opportunities for talents across the group’s leading brands and entities.
Applying to this job offers you the opportunity to join Volvo Group. Every day, you will be working with some of the sharpest and most creative brains in our field to be able to leave our society in better shape for the next generation. We are passionate about what we do, and we thrive on teamwork. We are almost 100,000 people united around the world by a culture of care, inclusiveness, and empowerment.
Volvo Group Digital Technology & Operations (DTO) is a new division. The organizational set up is structured around domains, digital products with functions for digital excellence to deliver outstanding customer experience.
Joining the new DTO division means being part of a fast-moving digital product-oriented organization where teams truly own what they build from idea to delivery. In DTO, we work in agile, cross-functional teams, mastering the latest technology, and creating outstanding digital experiences that make a real difference for our colleagues and Volvo Group customers around the world. We put people first and build our culture on trust, passion, customer success, change, and performance. If you want to grow, collaborate across functions and entities, and help shape the future of digital products within Volvo Group, DTO is a great place to be.
In some countries and for specific positions within Volvo Group Digital Technology & Operations, background checks (verification of selected information provided by the candidate) may be required, in accordance with local laws & regulations. If this is applicable to the role you have applied for, you will be informed.